CareerRiver

Principal Engineer — Product & Application Security

Freshworks Inc. · San Francisco Bay Area

📍 San Mateo, CA, usvia smartrecruitersPosted 2026-07-14
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Freshworks Inc..
Organizations everywhere struggle under the crushing costs and complexities of “solutions” that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business software has become a blocker instead of ways to get work done. There’s another option. Freshworks. With a fresh vision for how the world works. Freshworks Inc. builds uncomplicated service software that delivers exceptional employee and customer experiences. Our people-first approach to AI eliminates friction, helping businesses reduce complexity, lower cost-to-serve, and deliver faster, more human support through enterprise-grade yet easy-to-use CX and IT solutions. Nearly 75,000 companies, including Bridgestone, New Balance, Nucor, S&P Global, and Sony Music, trust Freshworks to power their Employee Experience (EX) and Customer Experience (CX) operations. Fresh vision. Real impact. Come build it with us. We are looking for a Principal Engineer — Product & Application Security to be the top technical authority for how Freshworks builds secure software. As an IC6 Principal, you set the multi-year security technical vision for our products and platform, make the calls on our hardest security-architecture problems, and are the person the company relies on when the stakes are highest — across a multi-tenant SaaS estate serving 72,000+ customer accounts and hundreds of integrations. As Freshworks evolves from a suite of service products into an AI-first system of business intelligence — with autonomous agents, a Knowledge and Context Graph, and a growing agentic surface — the security bar must rise with it. This role goes beyond leading individual reviews and remediations: you define the secure-by-design paradigms, reference architectures, and organization-wide standards that determine how thousands of engineers ship, and you drive the strategic bets (AI/agent security, supply-chain integrity, zero-trust data protection) that keep Freshworks ahead of the threat curve. You will operate as a company-wide force multiplier — writing code and reference implementations, setting technical direction that outlives any single project, mentoring Staff and Senior Staff security engineers, and partnering directly with VP Engineering, the CISO organization, and product leadership to make security a durable competitive advantage. Key Responsibilities Security Technical Vision & Strategy Own the multi-year technical vision and architecture strategy for product and application security across all Freshworks products (Freshdesk, Freshservice, and the shared Platform), and drive alignment on it across engineering and the CISO organization Define the secure-by-design reference architectures, paradigms, and organization-wide standards (authN/authZ, tenant isolation, data protection, secrets, API security) that thousands of engineers build against Set the strategic security agenda for the AI-first platform — securing the AI Agent Platform, Knowledge/Context Graph, and agentic workflows — anticipating threat classes before they reach production Act as the final technical decision-maker and tie-breaker on the hardest, highest-risk security-architecture trade-offs Product & Application Security Engineering Lead threat modeling and security design reviews for the most critical, cross-cutting, and highest-risk systems — including identity and access, the integrations/connector framework (300+ apps), and the agent runtime Set the standard for secure code review, manual and AI-assisted penetration testing, and vulnerability analysis; drive root-cause remediation strategies that eliminate whole vulnerability classes across the estate, not one bug at a time Architect and harden multi-tenant security controls: strict tenant isolation, authentication/authorization models, secrets management, data protection, and API gateway security Own the security design for AI/agentic features — prompt injection defense, tool-invocation authorization, non-human identity, and permission-scoped context access Left-Shift & Secure SDLC at Scale Define the organization-wide, AI-assisted left-shift strategy: how SAST, DAST (e.g., Snyk), SCA/dependency scanning, secret detection, and IaC scanning are embedded across every CI/CD pipeline to catch issues before production Set the direction for security tooling, automation, and paved-road frameworks and libraries that make the secure path the default path — including code-component asset inventory (API/SBOM/RBAC/secrets/integrations) and secure-by-default product hardening Own the software supply-chain security strategy: centralized software artifact repository management (e.g., Sonatype Nexus), code artifact repository guardrails, and CI/CD pipeline hardening Establish secure coding standards, golden patterns, and guardrails; operationalize threat modeling and maturity models (SAMM) across the product portfolio; and define the security quality gates the whole org is measured against Vulnerability Management & Incident Response Serve as the top technical escalation point for the most severe security incidents — leading investigation, containment strategy, and post-incident architectural hardening Set the risk-based prioritization framework for findings from internal testing, bug bounty, third-party pen tests, and researcher disclosures, and drive systemic fixes Shape the strategy for the bug bounty and responsible-disclosure program Technical Leadership & Influence Act as the recognized top IC authority for product security — mentoring and multiplying Staff and Senior Staff engineers and security champions, and raising the security bar across the entire engineering organization Influence company-level strategy: advise VP Engineering, the CISO organization, and product leadership; represent Freshworks' product-security posture

More San Francisco Bay Area jobs

San Francisco Bay Area jobs · Browse all locations